quicTokenHandler
The QuicTokenHandler used to generate and validate QUIC address-validation (Retry) tokens.
When null (the default), no address validation is performed and connections are accepted on the first Initial packet. Setting a handler enables stateless Retry: every new connection without a token receives a Retry packet and must restart the handshake, which adds one full round trip and roughly doubles the Initial packet processing per connection. Enable it when the endpoint is exposed to untrusted networks and needs protection against source-address spoofing and amplification attacks.
HmacQuicTokenHandler is provided as a secure implementation that signs tokens with HMAC-SHA256 and rejects forged or expired tokens. Callers may also supply a custom QuicTokenHandler to use a different signing strategy or integrate with external token services.